Hey subscribers!

Welcome to the first edition of The Frequency. This is my best attempt at an informative yet informal look into the world of AI security. I’m happy to be your liaison, or point guard (excuse the forced basketball reference, I’m still coming off the high of a Knicks championship run), and curate valuable information about AI security for all of you. In this issue, you’ll read about:

  • OpenAI’s new ChatGPT desktop app and our guide to deploy it safely 💻

  • Claude Tag. Slack’s newest integration

  • Updates to the EU AI Act 🏤

  • Harmonic Security’s Threat Engine!

The latest practical and actionable guide for you on AI governance

The New & Improved ChatGPT Desktop App

Me and my team looking at the new app. This is a real photo that was taken.

On July 9th, OpenAI merged Codex into one ChatGPT desktop app, bringing Chat, Work and Codex together as a single agent surface. See the official announcement from the OpenAI HQ here. The app can work across local files, desktop applications, websites, and connected business services. Those capabilities can also be used in longer-running assignments and scheduled workflows.

Ed Merrett, Director of Security & TechOps here at Harmonic Security, and the man I go to when I don’t know the answer to a question, pulled together a security practitioner's guide to deploying it safely: what to configure, in what order, and what to monitor.

What you should care about: The heart of it is that ChatGPT Work is a general business agent, not a developer tool (like Codex), and the merged desktop app puts it on employees' machines. So the first job is finding unmanaged and personal-account usage and pulling it into a workspace you control. From there, focus on three things: connector permissions scoped by action (read is a different risk from send or publish), conservative Codex sandbox defaults enforced through MDM, and the audit gap, because ChatGPT compliance logs capture prompts and responses but not files, actions or tool calls, so you need source-system logs to investigate anything.

The insights our team thinks matter the most

Tag you’re it: Claude Tag is new, a bit of a pain, but possibly here to stay

Anthropic recently introduced Claude Tag - it adds a shared Claude agent to selected Slack channels for Team and Enterprise customers. It can remember channel context, use approved tools and data, complete assignments asynchronously, schedule future work, and proactively surface relevant updates. Everyone in the channel can see and continue the agent’s work. 👨‍🏭

Why it matters for your security team: Several employees can direct the same persistent agent, creating different identity and accountability questions from a private AI conversation. If you’re an administrator, you should define which channels, tools, data, and memories each Claude identity can access. Initial testing should happen in a private channel with narrow permissions, spending limits, and activity logging enabled. Teams should also confirm that sensitive context cannot cross channel or departmental boundaries.

Laying down the law: EU AI transparency rules

The European Commission has finalized its guidance for Article 50 of the EU AI Act. The underlying transparency requirements take effect on August 2, 2026. They cover disclosure of direct AI interactions, machine-readable marking of synthetic content, visible disclosure of deepfakes, unreviewed AI text about matters of public interest, and notification when people are exposed to emotion-recognition or biometric-categorization systems. More in their FAQ here.

Why we care and why you should too: The greatest impact falls on public-facing AI systems and published content, not routine internal drafts created with ChatGPT or another assistant. Companies should inventory customer-facing bots, synthetic-media pipelines, and external publishing workflows, then establish who owns the required disclosures. Internal impact is more targeted, particularly for employee-facing bots and emotion or biometric systems used in the workplace.

A security practitioner spotlight on real AI builds solving security problems

A (Free) AI-Powered Threat Engine

If you're anything like me, you're sick of threat intel feeds that generate noise instead of anything you can act on.

So, the security team here at Harmonic built a Threat Engine that I wanted to share with the community. Instead of a static threat database, we wired live context straight into an agent running in Tines, pulling from our MDM, our codebase, our real tech stack. You can also feed it your own threat profile. So it's searching through a news article for technology we use AND it's checking against the actual threat actors and TTPs we care about. Every piece of incoming intel gets run against both before a human sees it.

It paid off faster than I expected. When Wiz published GhostApproval, the flaw hitting six AI coding assistants including Claude Code, the engine matched it against the tools our engineers at Harmonic actually use. It was flagged within minutes of the post going live. We weren't finding out on Twitter hours later and scrambling to figure out our exposure. This let's us focus on hunting or building detections the moment something relevant lands instead of days later.

We used Tines because it's fast to stand up, cloud-native, and handles the deterministic pulling, filtering, and transforming of data well. But the logic isn't Tines-specific.

WHAT WE’RE LISTENING TO RIGHT NOW 🎙

While I love sharing everything with regards to AI security, I also love music. Given that this is the first issue of The Frequency, and I am part of the marketing team here at Harmonic, I wanted to give you guys a bit of a behind-the-scenes look at what the marketing team and I are listening to right now.

If you find yourself obsessed with a new artist and want to share with the community, shoot me note 😃

Finally, I’m always looking for feedback. See something you liked, or something you didn’t? Want to see something in the next issue? Got a cool AI tool you want to showcase? Hit reply and let me know.

Catch you next time,
Tyler

Know a security lead who'd find this useful? Forward it their way.

And if this was forwarded to you, subscribe at harmonic.security/frequency